Create an API key for a workspace
Mints a service-account API key bound to the selected workspace. The calling credential must be user-owned, carry settings:write, and its user must currently be an owner or admin in the target workspace. The target must be visible within the calling credential’s brand; no white-label entitlement is required. Requested scopes can only stay equal to or become narrower than the calling credential’s scopes. A child key cannot outlive a finite calling credential. The target may still be awaiting plan activation, but a suspended target is rejected. The plaintext key is returned exactly once with Cache-Control: no-store; do not retry automatically because each successful request creates a new key.
Authorizations
API key (fam_..., created under Settings → API Keys) or an OAuth 2.0 access token (fam_at_...). Keys can be restricted to scopes such as assistants:read, calls:write, campaigns:write, automations:read, dashboards:read, dashboards:write, leads:write, segments:write, loop:read, loop:write, phone_numbers:write, sip_trunks:write, knowledge:write, voices:read, billing:read, settings:write, platform:read, platform:write; a *:write scope implies the matching *:read. Automation and dashboard endpoints also accept the legacy calls:* scope. Keys without scope restrictions have full access.
Path Parameters
Target workspace UUID from GET /workspaces.
Body
100Must be a subset of the calling credential's own scopes — a key can never mint another key with broader access than itself. Omitted defaults to the calling credential's own scopes (or, if the credential itself has unrestricted access, every scope).
50Requested lifetime. Omitted inherits a finite calling credential's expiry, or means no expiry when the caller itself does not expire.
1 <= x <= 365Response
The target-workspace key, including its one-time plaintext secret.
A newly-minted API key, including the plaintext secret.